Vulnerability record · CVE-2014-6593 · published 21 January 2015
CVE-2014-6593: Oracle Java JSSE flaw allows remote confidentiality and integrity impact
Oracle · Jrockit
CVE-2014-6593 is an unspecified vulnerability in the JSSE component of Oracle Java SE (5.0u75, 6u85, 7u72, 8u25), Java SE Embedded (7u71, 8u6) and JRockit (27.8.4, 28.3.4). Oracle's advisory and the record give no technical detail on the root cause, but the flaw is remotely reachable and affects both confidentiality and integrity. It matters because JSSE underpins TLS in Java, so any weakness there can undermine the security of Java-based network communications.
Description
Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit 27.8.4 and 28.3.4 allows remote attackers to affect confidentiality and integrity via vectors related to JSSE.
AV:N/AC:H/Au:N/C:P/I:P/A:N
Automated analysis
medium priorityCVSS v2 rates it MEDIUM (4.0) with high access complexity and no confirmed exploitation, but the high EPSS score and broad Java deployment warrant timely patching.
What it is
CVE-2014-6593 is an unspecified vulnerability in the JSSE component of Oracle Java SE (5.0u75, 6u85, 7u72, 8u25), Java SE Embedded (7u71, 8u6) and JRockit (27.8.4, 28.3.4). Oracle's advisory and the record give no technical detail on the root cause, but the flaw is remotely reachable and affects both confidentiality and integrity. It matters because JSSE underpins TLS in Java, so any weakness there can undermine the security of Java-based network communications.
Impact
A remote attacker can affect the confidentiality and integrity of data handled by the affected Java runtime, potentially reading or altering information protected by JSSE. No code execution or availability impact is stated in the record.
Attack surface
The CVSS v2 vector AV:N/AC:H/Au:N/C:P/I:P/A:N indicates the flaw is reachable over the network with no authentication required, but exploitation is difficult due to high access complexity. No user interaction is specified in the record.
Exploitation
The record is not listed in CISA KEV and no reference carries an exploit tag, so confirmed in-the-wild exploitation is not established; EPSS is high (0.66374, 99.2nd percentile), indicating elevated predicted exploitation likelihood.
What to do
- Apply the Oracle Critical Patch Update January 2015 fixes for Java SE, Java SE Embedded and JRockit, or the corresponding vendor updates (Red Hat, Debian, Ubuntu, SUSE, Gentoo, HP, VMware, McAfee).
- Upgrade to a Java release newer than the affected versions listed (5.0u75, 6u85, 7u72, 8u25, Embedded 7u71/8u6, JRockit 27.8.4/28.3.4).
- Inventory Java and JRockit installations across servers and endpoints and confirm none remain on the affected builds.
- Where Java is not required, remove it or restrict network exposure of Java-based services to reduce the attack surface.
Detection
- Search asset inventories and vulnerability scans for Java/JRockit versions matching the affected builds.
- Monitor network traffic to and from Java-based services for anomalous TLS/JSSE behavior, though the record provides no specific signature.
- Review vendor patch and package management logs to confirm JSSE-related Java updates were applied.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2014-6593 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-6593), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.